An input validation issue exists in WebKit's handling of floating point data types. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This issue is addressed through improved validation of floating point values. Credit to Luke Wagner of Mozilla for reporting this issue.
References:
https://bugs.webkit.org/show_bug.cgi?id=43461http://trac.webkit.org/changeset/64706